bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, October 1, 2026

Amazon Ion Python Vulnerability Requires Immediate Update

Amazon Ion Python versions before 0.15.0 have a nasty recursion bug (CVE-2026-104020) that lets attackers crash your app with deeply nested Ion values. This denial-of-service vulnerability is marked Important, so you'll want to upgrade ASAP if you're using this library. Patch to version 0.15.0 or later to stay safe.

source: [aws/security-bulletin]